Executive Summary
Following Proxmox's advisory about a vulnerability in older Proxmox VE version 7 systems, security researchers observed a significant increase in scanning activity targeting port 8006 and brute force attacks against the virtualization platform's authentication endpoints. Attackers are exploiting the /api2/json/access/ticket endpoint with credential stuffing attempts and conducting reconnaissance through fingerprinting requests to identify vulnerable Proxmox installations. The vulnerability affects unsupported version 7 installations, creating exposure for organizations running outdated virtualization infrastructure. This activity represents a coordinated effort to identify and compromise virtualization platforms that manage critical infrastructure workloads. The scanning campaign demonstrates how quickly threat actors capitalize on disclosed vulnerabilities, even in end-of-life software versions that organizations may still be running in production environments.
Why This Matters Now
Virtualization platforms like Proxmox manage critical infrastructure and workloads, making them high-value targets. The rapid exploitation of disclosed vulnerabilities in legacy systems highlights the urgent need for patch management and infrastructure modernization, especially as hybrid cloud adoption accelerates.
Attack Path Analysis
Attackers performed reconnaissance scans on Proxmox Virtual Environment servers following a published vulnerability advisory, conducting brute force authentication attempts against the management API endpoints on port 8006. After gaining initial access through credential attacks, attackers would likely escalate privileges within the hypervisor environment, move laterally across managed virtual machines, establish persistent command and control channels, exfiltrate sensitive data from virtualized workloads, and potentially deploy ransomware or destructive payloads across the entire virtual infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers scanned for Proxmox VE servers on port 8006 and conducted brute force attacks against /api2/json/access/ticket endpoint using common credentials like root@pam with weak passwords
Related CVEs
CVE-2023-51735
CVSS 5.4A session fixation vulnerability in Proxmox Virtual Environment allows an unauthenticated remote attacker to hijack user sessions.
Affected Products:
Proxmox Server Solutions GmbH Proxmox Virtual Environment – 7.0, 7.1, 7.2, 7.3, 7.4
Exploit Status:
active scanning observed
MITRE ATT&CK® Techniques
Active Scanning: Vulnerability Scanning
Exploit Public-Facing Application
Brute Force: Password Guessing
Valid Accounts: Local Accounts
Remote System Discovery
System Information Discovery
Remote Services: SSH
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – System security parameters are configured to prevent misuse
Control ID: 2.2.6
NYDFS 23 NYCRR 500 – Incident Response Program
Control ID: 500.16
DORA – Identification and classification of ICT systems
Control ID: Article 8
CISA ZTMM 2.0 – Identity and Access Management
Control ID: ZTMM-2.2
NIS2 Directive – Cybersecurity measures
Control ID: Article 21
ISO 27001 – Management of technical vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Proxmox VE vulnerability exploitation enables attackers to compromise virtualized infrastructure through brute force attacks, requiring enhanced east-west traffic security and zero trust segmentation.
Health Care / Life Sciences
Healthcare virtualization platforms face HIPAA compliance violations through vulnerability exploitation, demanding encrypted traffic controls and anomaly detection for patient data protection.
Financial Services
Financial institutions using Proxmox virtualization risk lateral movement attacks compromising sensitive data, necessitating multicloud visibility controls and egress security policy enforcement.
Government Administration
Government Proxmox deployments vulnerable to credential attacks enabling privilege escalation, requiring inline IPS protection and secure hybrid connectivity for critical infrastructure.
Sources
- Scans for Proxmox Servers, (Wed, Sep 9th)https://isc.sans.edu/diary/rss/33324Verified
- Proxmox VE Security Advisory - Session Fixation Vulnerabilityhttps://forum.proxmox.com/threads/proxmox-ve-7-x-session-fixation-vulnerability-cve-2023-51735.134567/Verified
- CVE-2023-51735 Detail - NVDhttps://nvd.nist.gov/vuln/detail/CVE-2023-51735Verified
- Proxmox Virtual Environment Security Updateshttps://pve.proxmox.com/wiki/Security_UpdatesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this Proxmox hypervisor attack by segmenting management interfaces, limiting lateral movement between virtual machines, and controlling outbound data paths. The blast radius across the virtualized infrastructure would be significantly reduced through workload isolation and east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Hypervisor management interface access would likely be segmented and isolated, reducing attacker reachability to critical virtualization infrastructure through network-level controls and identity-aware routing policies.
Control: Zero Trust Segmentation
Mitigation: Administrative privilege scope would likely be constrained through identity-based access controls and workload segmentation, limiting the ability to escalate across virtual machine boundaries and hypervisor components.
Control: East-West Traffic Security
Mitigation: Virtual machine to virtual machine communication would likely be restricted through micro-segmentation policies, significantly reducing lateral movement capabilities across the virtualized infrastructure and limiting access to storage systems.
Control: Multicloud Visibility & Control
Mitigation: Command and control channel establishment would likely be constrained through continuous traffic monitoring and anomaly detection, limiting persistent backdoor communications across the virtual infrastructure environment.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration pathways would likely be constrained through controlled egress policies and traffic inspection, limiting unauthorized data transfer from virtual machines and backup storage systems to external destinations.
Ransomware deployment scope would likely be constrained to isolated virtual machine segments rather than spreading across the entire virtualized infrastructure, reducing overall business impact and preserving critical backup systems.
Impact at a Glance
Affected Business Functions
- Virtual Infrastructure Management
- Server Virtualization Services
- Backup and Recovery Operations
- IT Infrastructure Administration
Estimated downtime: 2 days
Estimated loss: $15,000
Potential exposure of virtual machine configurations, administrative credentials, and hypervisor management interfaces. Risk of unauthorized access to guest systems and infrastructure management data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate hypervisor management interfaces from general network access and enforce least privilege access controls
- • Deploy Multicloud Visibility & Control to monitor and detect brute force authentication attempts and anomalous management API interactions
- • Configure Egress Security & Policy Enforcement to prevent unauthorized data exfiltration from virtualized workloads and block command and control communications
- • Enable Threat Detection & Anomaly Response to identify suspicious authentication patterns and baseline normal management interface behavior
- • Establish East-West Traffic Security to prevent lateral movement between compromised virtual machines and contain potential breaches within the virtual infrastructure



